US2025279893A1PendingUtilityA1

Providing Authentication in a Network

Assignee: COMCAST CABLE COMM LLCPriority: Mar 1, 2024Filed: Mar 1, 2024Published: Sep 4, 2025
Est. expiryMar 1, 2044(~17.6 yrs left)· nominal 20-yr term from priority
H04W 12/06H04L 9/3226H04W 84/12H04W 12/03
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods are described for use of encryption methods for multiple network groups with different passkeys. A gateway may be configured so that the gateway may manage an authentication process of particular or pre-identified devices wireless devices differently from other devices. The gateway may determine if the device is a pre-identified device and if the passkey used by the device is an authorized passkey, and may authenticate the device using a particular encryption method.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 receiving, by a gateway from a wireless device, one or more first messages requesting connection to a wireless network associated with a wireless network identifier, wherein the one or more messages comprise a passkey and an identifier of the wireless device;   determining not to allow connection to the wireless network based on the passkey and a first wireless encryption protocol associated with the wireless network;   determining that the passkey is associated with a second wireless encryption protocol;   establishing, using the passkey and the second wireless encryption protocol, a connection between the wireless device and the wireless network.   
     
     
         2 . The method of  claim 1 , further comprising:
 sending, by the gateway, one or more messages comprising one or more of:   the wireless network identifier;   an indication indicating connection to the wireless network; and   an indication that the first wireless encryption protocol is used.   
     
     
         3 . The method of  claim 1 , wherein the one or more messages requesting connection to the wireless network further comprises the wireless network identifier and an acknowledgement that the first wireless encryption protocol is used. 
     
     
         4 . The method of  claim 1 , wherein the first wireless encryption protocol is Wi-Fi protected access  3  using simultaneous authentication of equals (WPA3/SAE) authentication and wherein the second wireless encryption protocol is Wi-Fi protected access 2 using multi-pre-share key (WPA2/multi-PSK) authentication. 
     
     
         5 . The method of  claim 1 , wherein the first wireless encryption protocol only allows a single passkey and wherein the second wireless encryption protocol allows multiple passkeys. 
     
     
         6 . The method of  claim 1 , further comprising:
 receiving, from a second wireless device, one or more messages requesting connection to the wireless network, wherein the one or more messages comprise a second passkey different from the passkey;   disallowing connection to the wireless network based on the second passkey and the first wireless encryption protocol; and   allowing connection to the wireless network based on the second passkey and the second wireless encryption protocol.   
     
     
         7 . The method of  claim 1 , wherein the wireless network identifier is a service set identifier (SSID). 
     
     
         8 . The method of  claim 1 , further comprising causing, by the gateway, configuration of a switch to deny, based on the identifier of the wireless device, access to one or more network resources. 
     
     
         9 . The method of  claim 1 , further comprising:
 determining, based on the identifier of the wireless device, that communication with the wireless device is authenticated using the second wireless encryption protocol.   
     
     
         10 . The method of  claim 1 , further comprising:
 controlling access, based on the identifier of the wireless device, to the wireless network, wherein controlling access comprises at least one of:   allowing access to one or more network resources;   duration-limiting access to all of the one or more network resources; or   scheduled-limiting access to all of the one or more network resources.   
     
     
         11 . The method of  claim 1 , wherein the access point comprises a Wi-Fi driver and Wi-Fi stack software; and further comprising:
 sending, by the Wi-Fi driver and to the Wi-Fi stack, a second message comprising the identifier of the wireless device;   generating, by the stack, based on the passkey corresponding to the second wireless encryption protocol, a third message comprising an indication to authenticate a connection based on the second wireless encryption protocol;   sending, by the stack and to the driver, the third message; and   sending, by the driver and to the wireless device, the third message.   
     
     
         12 . A method comprising:
 sending, by a gateway, one or more first messages comprising an identifier of a wireless network associated with the gateway and an indication of the first wireless encryption protocol;   receiving, from a wireless device, one or more second messages requesting connection to the wireless network, wherein the one or more second messages comprise a second passkey and an identifier of the wireless device;   determining, based on the second passkey, that the second passkey corresponds to a second wireless encryption protocol;   sending, to the wireless device, based on determining that the second passkey corresponds to the second wireless encryption protocol, one or more third messages comprising an indication that authentication of the wireless device will use the second wireless encryption protocol; and   establishing, a connection of the wireless device to the wireless network using the second wireless encryption protocol and the second passkey.   
     
     
         13 . The method of  claim 12 , wherein the identifier of the wireless network is a service set identifier (SSID). 
     
     
         14 . The method of  claim 12 , wherein the second passkey corresponds to a wireless network group, and wherein the wireless network group has access to one or more network resources. 
     
     
         15 . The method of  claim 12 , further comprising:
 determining that the identifier of the wireless device corresponds to an identifier of one or more wireless devices pre-approved to connect to the wireless network using one of the plurality of passkeys.   
     
     
         16 . The method of  claim 12 , further comprising controlling access, based on the identifier of the wireless device, to one or more network resources. 
     
     
         17 . A method comprising:
 receiving, by a gateway and from a wireless device, one or more first messages comprising a passkey and an identifier of the wireless device and requesting connection to a wireless network;   determining not to allow connection to the wireless network based on the passkey and a first wireless encryption protocol associated with the wireless network;   establishing a connection between the wireless device and the wireless network using a second wireless encryption protocol associated with the passkey;   causing, by the gateway, configuration of a network switch to deny, based on the identifier, access to one or more network resources of the wireless network; and   sending, to the wireless device, one or more second messages comprising an indication of the connection of the wireless device to the wireless network.   
     
     
         18 . The method of  claim 17 , wherein the causing configuration of the network switch to deny access to the wireless device is further based on the passkey. 
     
     
         19 . The method of  claim 17 , wherein the identifier of the wireless device is a media access control identification (MAC ID). 
     
     
         20 . The method of  claim 17 , wherein the first wireless encryption protocol is Wi-Fi protected access 3/simultaneous authentication of equals (WPA3/SAE) and the second wireless encryption protocol is Wi-Fi protected access 2/multiple pre-shared keys (WPA2/multi-PSK).

Join the waitlist — get patent alerts

Track US2025279893A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.